PT-2016-4028 · Symantec · Data Center Security: Server Advanced Server+2

Publicado

2016-06-08

·

Atualizado

2021-09-09

·

CVE-2015-8798

CVSS v2.0

7.7

Alta

VetorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec Embedded Security: Critical System Protection (SES:CSP) versions 1.0.x through 1.0 before MP5 Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) version 6.5.0 before MP1 Critical System Protection (SCSP) versions prior to 5.2.9 MP6 Data Center Security: Server Advanced Server (DCS:SA) versions 6.x through 6.5 before MP1 and version 6.6 before MP1 Data Center Security: Server Advanced Server and Agents (DCS:SA) versions prior to 6.6 MP1
Description A directory traversal issue in the Management Server allows remote authenticated users to execute arbitrary code via unspecified vectors.
Recommendations For Symantec Embedded Security: Critical System Protection (SES:CSP) versions 1.0.x, update to 1.0 MP5 or later. For Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) version 6.5.0, update to MP1 or later. For Critical System Protection (SCSP), update to 5.2.9 MP6 or later. For Data Center Security: Server Advanced Server (DCS:SA) versions 6.x, update to 6.5 MP1 or later, and for version 6.6, update to MP1 or later. For Data Center Security: Server Advanced Server and Agents (DCS:SA), update to 6.6 MP1 or later.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8798

Produtos afetados

Critical System Protection
Data Center Security: Server Advanced Server
Symantec Embedded Security: Critical System Protection